Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping

Security Affairs

Overview

A significant data leak has occurred involving 7.3 million user profiles from Chess.com, which surfaced in a 15.5 GB file posted on two data-leak websites. Researchers confirm that the data is legitimate and appears to have been obtained through large-scale scraping rather than a direct breach of Chess.com's servers. This incident raises concerns about user privacy, as exposed data can include personal information and potentially sensitive account details. The fact that the data is being offered for free suggests that it was not stolen for immediate profit but rather to be shared widely, which could lead to further exploitation of the affected users. It’s crucial for Chess.com users to be aware of this leak and take steps to secure their accounts, such as changing passwords and enabling two-factor authentication.

Key Takeaways

  • Affected Systems: Chess.com user profiles
  • Action Required: Users should change their passwords and enable two-factor authentication.
  • Timeline: Newly disclosed

Original Article Summary

7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 million chess.com user records showed up on two data-leak […]

Impact

Chess.com user profiles

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Newly disclosed

Remediation

Users should change their passwords and enable two-factor authentication.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations

Infosecurity Magazine

Researchers have confirmed that the cyber extortion group ExfilSquad has accessed and stolen sensitive data from at least 13 different organizations. This data has been published by the group through torrents, making it publicly available. The nature of the stolen information remains unspecified, but the breach underscores significant security vulnerabilities within these organizations. As the leaked data could potentially be used for further attacks or identity theft, companies need to assess their security measures and respond swiftly to mitigate any potential fallout. This incident serves as a reminder of the ongoing risks posed by cybercriminals who exploit weaknesses in security protocols.

Aug 14, 2026

Max severity SAP Commerce Cloud flaw now targeted in attacks

BleepingComputer

A recently patched vulnerability in SAP Commerce Cloud, classified as a maximum-severity remote code execution flaw, is now being actively targeted by attackers. The flaw was fixed just three days ago, and threat intelligence firm Defused has reported that cybercriminals are already exploiting it. This vulnerability puts users of SAP Commerce Cloud at risk, as it allows unauthorized code execution, potentially leading to data breaches or service disruptions. Companies using this platform need to ensure they apply the latest security updates to protect their systems. The urgency of the situation is underscored by the rapid exploitation following the announcement of the patch, making swift action essential for affected organizations.

Aug 14, 2026

CISA adds Metabase, Windows and Cisco Secure Firewall flaws to exploited vulnerabilities list

SCM feed for Latest

The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its catalog of exploited vulnerabilities. These include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898). These flaws could allow attackers to exploit systems running affected software, potentially leading to unauthorized access or data breaches. Organizations using these products need to take immediate action to protect their systems. Awareness and prompt updates are essential to mitigate the risks associated with these vulnerabilities.

Aug 14, 2026

New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies

Infosecurity Magazine

A new botnet called Evooo1Bot has emerged, built on the Mirai framework and featuring enhanced capabilities. This botnet is designed to convert compromised edge devices into persistent proxies, which can be exploited for various malicious activities. Researchers have noted that this could significantly impact Internet of Things (IoT) devices, making them potential tools for cybercriminals. The ability to create proxies means that attackers can mask their identity and amplify their operations, raising concerns about privacy and security. Users of affected devices need to be vigilant and improve their security measures to prevent being turned into unwitting participants in these attacks.

Aug 14, 2026

Shell investigates 'potential incident' after Clop data theft claims

BleepingComputer

Shell is currently investigating a potential security incident after the Clop ransomware group claimed to have stolen 89GB of sensitive data from the company. The group is known for targeting large organizations and demanding ransom payments to prevent the public release of stolen information. Although Shell has not confirmed the specifics of the data taken, the incident raises concerns about the security of sensitive corporate information and the potential impacts on operations and reputation. As the investigation unfolds, it remains to be seen how the company will respond and whether any sensitive information has already been compromised. This incident serves as a reminder for all organizations to bolster their cybersecurity measures against ransomware attacks.

Aug 14, 2026

Trivy, Not LiteLLM Behind the 2,500 Org Compromise

SecurityWeek

A recent analysis revealed that Trivy, a popular open-source vulnerability scanner, was responsible for exposing over 2,500 organizations to security risks, rather than malicious LiteLLM packages. Researchers noted that more than 95% of these companies had vulnerabilities before the LiteLLM packages were released. This incident raises concerns about the security practices surrounding the use of scanning tools and the potential for software vulnerabilities to be exploited, impacting organizations' defenses. Companies using Trivy should review their configurations and assess their vulnerability management processes to prevent similar compromises in the future. This situation serves as a reminder for organizations to stay vigilant about their security practices and regularly update their tools.

Aug 14, 2026